
CVE-2018-16373
Frog CMS 0.9.5 has an Upload > vulnerability that can create files via > /admin/?/plugin/file_manager/save

Frog CMS 0.9.5 has an Upload > vulnerability that can create files via > /admin/?/plugin/file_manager/save

xss for gitbook

Python toolkit for authorized testing of CVE-2021-43798 Grafana path traversal, with arbitrary file read PoC, secret decryption, and user hash export…

An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if…

ppsx file generator for cve-2017-8570 (based on bhdresh/cve-2017-8570)

Proof-of-concept exploit for CVE-2024-22514 enabling remote code execution in iSpyConnect Agent DVR 5.1.6.0 via malicious objects.xml file…

Exploit for CVE-2024-43044 enabling arbitrary file read from Jenkins controller to extract and decrypt credentials.xml using secret keys.

CVE-2024-23692 | HFS 2.3m/2.4-RC07 RCE vulnerability fix

CMSmadesimple 2.2.18 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed…

WBCE 1.6.1 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will launch…

Powershell script that dumps Chrome and Edge version to a text file in order to determine if you need to update due to CVE-2022-1096

Python-based proof-of-concept exploit for CVE-2024-7399 with check, command execution, and file upload capabilities against HTTPS endpoints.

This python file will decrypt the configurationFile used by hikvision cameras vulnerable to CVE-2017-7921.

Automated exploitation tool for CVE-2021-3019 that reads target IPs from a text file and executes the exploit against HTTP endpoints.

Chamilo LMS Unauthenticated Big Upload File that allows remote code execution

Decrypts Hikvision IP camera configuration files extracted via CVE-2017-7921 authentication bypass, recovering user credentials from weakly encrypted…

Decrypts Hikvision IP camera configuration files extracted via CVE-2017-7921 authentication bypass, revealing user credentials and device settings.

Java-based exploit tool for CVE-2017-13156 that bypasses Android APK signature verification by appending a DEX file to an existing APK, enabling code…